Skip to content
Cortex
How it worksMoving from AnkiPricingFAQ
Notify me
How it worksMoving from AnkiPricingFAQNotify me

Privacy Policy

Last revised: October 10, 2026

Cortex is a product of Joshua Hoffman ("we," "us," or "our"), located in the United States. This Privacy Policy explains what information we collect when you use the Cortex application and related services ("the Service"), how we use it, and your rights with respect to it.

Please read this policy alongside our Terms of Service.

Cortex stores downloaded study content and account data on your devices and synchronizes account content with our servers. Local processing does not by itself send information to a provider; account services, synchronization, analytics, and cloud AI process the information described below.

  • 1. Information we collect
  • 2. How we use your information
  • 3. Third-party services
  • 4. Website tracking
  • 5. AI features and data
  • 6. Third-party data sharing
  • 7. Data retention
  • 8. Children's privacy
  • 9. Your rights and choices
  • 10. California privacy rights
  • 11. Data security
  • 12. International data transfers
  • 13. Changes to this policy
  • 14. Contact

1. Information we collect

Information you provide

Account information. We collect your verified email address, account identifier, sign-in provider, and the profile and onboarding information you provide, such as your username, private name, avatar, study interests, and familiarity with flashcards. If you choose Apple or Google sign-in, we receive the account information that provider makes available for authentication, which may include an identifier, name, email address, or Apple private relay email address. Your public username and relevant membership details may be visible to others as described in Section 6.

Card content. We store the flashcards, decks, notes, and associated media (images, audio) that you create or import into the Service.

Imported content. When you import supported content, Cortex retains the converted cards, supported media, and any study history you choose to import. An import may also keep identifiers needed to match content during reimport. Not every file or item in an import package is converted or uploaded.

Shared deck and course content. We store the shared content, course-private fields and media, membership requests, invitations, suggestions, revisions, and moderation records you create through the Service. The audience for that information depends on the deck, course, and your role, as described in Section 6.

Support communications. If you contact us for support, we retain records of that correspondence.

Launch notifications. If you join the launch notification list on our website, we collect your email address, signup date and source, the signup consent you provided, and email-delivery and engagement information, including opens and link clicks. We use this information to send a signup acknowledgement and the App Store launch notification you asked for, and to measure engagement with those messages. Joining the list does not create a Cortex app account or grant access to the app.

Information generated by your use of the service

Review history. We store your question review history, including ratings (Again, Hard, Good, Easy), review timestamps, and FSRS-based scheduler parameters. This data is fundamental to the spaced repetition functionality of the Service.

Study session metadata. We collect information about your study sessions, including session duration, number of questions reviewed, and streak data.

Sync metadata. Synchronization produces technical records such as installation and request identifiers, processing timestamps, and transfer status, used to deliver updates across devices and diagnose failures.

Device and platform information. We collect basic device type and operating system information to support troubleshooting and usage analytics.

AI inputs, results, and usage. When you use an AI feature, we process the content and instructions needed for your request, the resulting suggestions or other output, and technical usage records. Depending on the feature, inputs may include selected document passages, card content, search terms, images, audio, or transcripts. Section 5 explains the processing, providers, and your choices.

App analytics and error reports. We use PostHog to understand feature use and diagnose errors. App events include a Cortex account identifier, selected feature and screen names, app/device information, and technical error details. Our product analytics events exclude card text, media, names, email addresses, and free-form search or document text. Flutter error reports remove exception messages before sending diagnostic details. Native crash reports may contain stack traces and technical crash information. Session replay is disabled. Account identifiers are personal data, even when a person's name is not included.

Database reporting. A separate PostHog connection processes account, onboarding, and subscription information, including account identifiers and email addresses, together with plan and product reference data. This connection is separate from the app event filters.

Subscription information. RevenueCat receives your Cortex account identifier and email address, purchase and receipt information, and subscription status to manage entitlements and support purchase inquiries. Apple processes App Store payments. We do not receive your full payment-card details from Apple.

App updates. Shorebird delivers app patches. Update requests include technical information needed to select and deliver a compatible patch, such as app release, patch, platform, and architecture information. Its infrastructure may also log the request's IP address. Update delivery does not require your card content.

Log data. Infrastructure providers generate request and security logs that may include your IP address, request timestamps, and technical information about authentication, database access, storage, and app updates. We use logs to operate the Service, investigate failures, and prevent abuse. Retention is described in Section 7.

2. How we use your information

We use the information we collect for the following purposes:

  • Providing the service. Storing your cards, processing syncs, and powering the spaced repetition scheduler.
  • AI assistance. Processing the material you select to help you find, understand, create, edit, or organize study content, including PDF search suggestions, as described in Section 5.
  • Account management. Sending password resets, security alerts, and essential account communications.
  • Transactional email. Delivering essential email through Resend (for example verification, password reset, and security notices).
  • Requested communications. Sending the launch-list acknowledgement and App Store launch notification you requested through Loops, responding to product inquiries, and measuring email opens and link clicks. You can unsubscribe from launch-list messages.
  • Subscription management. Processing and tracking your subscription status through RevenueCat.
  • Product analytics and reporting. Measuring feature use, account setup, subscriptions, and technical reliability through PostHog to operate and improve Cortex. Where individual-level data is unnecessary, we use aggregated or de-identified information.
  • Learning research. We may use de-identified and aggregated study metrics for research into learning and spaced repetition, including collaboration with research institutions. Section 6 describes the safeguards and research opt-out. This permission does not include commercial data sharing.
  • Customer support. Responding to your questions and investigating issues you report.
  • Legal compliance. Meeting our obligations under applicable law.

3. Third-party services

We use the providers below to operate the Service. They receive information relevant to the services they perform. Apple and Google also process information under their own policies when you use their sign-in or store services.

ServicePurposeData involvedPrivacy policy
SupabaseAuthentication, database, media storage, and backend services supporting Cortex's own sync serviceAccount and profile data, cards and media, review history, collaboration records, and technical logsSupabase Privacy Policy
RevenueCatPurchase verification, subscriptions, and entitlement managementCortex account identifier and email, purchase/receipt information, and subscription statusRevenueCat Privacy Policy
PostHogApp analytics, error reporting, and database reportingThe app events and account/onboarding/subscription records described in Section 1PostHog Privacy Policy
OpenAIAI processing through its APISelected content and instructions needed for an AI request, generated results, and technical request metadata, as described in Section 5OpenAI API Data Controls; Data Processing Addendum; Privacy Policy
ResendSign-in, account, and transactional email deliveryRecipient email address, email content, message metadata, and delivery statusResend Privacy Policy
LoopsWebsite launch notification signup and email deliveryEmail address, signup source, mailing-list preferences, delivery information, email opens, and link clicksLoops Privacy Policy
ShorebirdApp update and patch deliveryApp release/patch, platform and architecture information, and network request logs that may include IP addressesShorebird Privacy Policy
AppleSign in with Apple and App Store purchases on iPhone, iPad, and MacProvider account/sign-in information and purchase information, as applicableApple Privacy Policy
GoogleGoogle sign-in, when you select itProvider account identifier, email, and profile information made available for sign-inGoogle Privacy Policy

We do not sell or rent your personal information. Research use is limited as described in Section 6.

4. Website tracking

The marketing website does not currently run website analytics or advertising trackers. Its launch notification form sends your signup to our Supabase backend and Loops for the acknowledgement and App Store launch notification you request. These emails track opens and link clicks to measure engagement. Email-client privacy features and automated scanners can affect those measurements. You can unsubscribe through the links in the messages or by contacting us; repeat signup requests do not override an existing unsubscribe preference. App analytics and database reporting are described in Section 1.

5. AI features and data

Scope and choice. AI assistance is optional. This section covers AI-assisted search and matching, document analysis and text extraction, explanations and summaries, creating or editing study content, organizing cards, and image or audio processing when those features are available. We process content for AI when you request assistance or explicitly enable ongoing AI processing. Ordinary use of Cortex does not authorize sending your whole library to an AI provider.

Information processed. We use only the content and context needed for the task. Depending on the feature, this may include your instructions, selected document pages or passages, search terms, relevant card fields and organization information, images, audio, transcripts, and generated results. Content you select may itself contain personal information. Semantic search may also create numerical representations of selected text, called embeddings, to find related content. These representations remain subject to the same access and privacy protections as the content they represent.

Sensitive information. Cloud AI is intended for educational study material. Do not submit identifiable patient records or other sensitive personal records. General medical or other educational subject matter is different from personal information about an identifiable person. Requesting AI assistance does not provide consent on behalf of another person.

PDF search. When you request AI term suggestions, Cortex extracts readable text on your device and sends text and page numbers from the pages included in your search, together with term wording used to avoid duplicate suggestions, through our backend to OpenAI. This operation does not send the PDF file, excluded-page text, or your full card library.

Providers. We use OpenAI's API for cloud AI processing. OpenAI processes request content under our customer agreement and applicable data-processing terms; its general Privacy Policy does not govern content it processes on behalf of API customers. The links in Section 3 include its API data controls and Data Processing Addendum.

No model training. OpenAI does not use content sent through Cortex's API integration, including your document text, card content, instructions, and generated results, to train or improve its AI models. We keep provider data-sharing and training opt-ins disabled. Cortex also does not use your AI inputs or results to train or fine-tune AI models. We require equivalent no-training protections before using another cloud AI provider.

Storage and operational records. The PDF term-suggestion service processes source text and suggestions to return the result; it does not store them in its usage records or routine analytics and error reports. We keep account-linked operation records, request identifiers, timestamps, status, and usage and cost information to manage access, allowances, reliability, abuse prevention, and billing. Results you choose to save as cards or other account content are handled under the storage, sync, sharing, and deletion rules in this policy.

Provider retention. We disable saved-response storage for current OpenAI text requests, but OpenAI may retain prompts, results, and related metadata in abuse-monitoring logs for up to 30 days by default, or longer where required by law or reasonably necessary to prevent harm. Sections 7, 9, and 12 apply to AI records, privacy requests, and international processing.

Your control and future changes. You can use available manual workflows without requesting AI assistance. If a feature introduces materially different data, purposes, providers, retention, or sharing, we will update the relevant disclosures and provide any notice or consent required before that processing begins.

6. Third-party data sharing

Shared decks and courses

Content you publish in a shared deck is available to users authorized to access that deck. Public decks can be discovered and joined under the Service's access rules; invite-only decks restrict admission. Course-private fields and their media are available only through the relevant course's authorization, not to every deck subscriber. Being a deck owner or moderator does not, by itself, grant access to a course's private content.

Deck and course owners and authorized moderators can see the information needed to manage their community, including public usernames and email addresses in invitation and membership-request workflows, submitted suggestions, and moderation history. Your private personalization name is not shown in those intake workflows. Contributions and decisions may be attributed to your account. Your personal notes, schedules, and review history remain account-owned; another person's deck or course role does not by itself give them access to that personal study data.

Shared contributions and moderation records can remain after you leave a deck or course or delete your account. Section 7 explains this retention. Do not publish information you are not authorized to share.

De-identified learning research

We may use de-identified and aggregated study metrics, such as review outcomes, retention estimates, and study patterns, to research learning and spaced repetition. We may collaborate with research institutions and educational organizations for those purposes. This does not authorize selling datasets or sharing them with commercial partners for advertising, profiling, or unrelated commercial purposes.

Research use is limited to datasets prepared without card text, media, private notes, email addresses, or account identifiers. Before research use or sharing, we must assess identification risks and aggregate or remove details that could identify a person, including small groups where necessary. Research recipients must agree to use the data only for the research purpose, without re-identification or onward disclosure. Published results must not identify individual users.

Research opt-out. To exclude your data from future research datasets, email hello@cortexcards.app with the subject "Research Opt-Out" and your Cortex account email. We will handle your request under the deadlines described in Section 9. Opting out does not affect access to Cortex. Once data has been irreversibly anonymized so that it cannot be linked back to you, we may no longer be able to remove your contribution from that dataset or published aggregate results. The opt-out does not stop operational analytics and reporting described in Sections 1 and 2, or limit your separate legal rights.

Legal requirements

We may disclose information when legally required, or when reasonably necessary to protect rights, investigate abuse, or protect the safety of users or the public, subject to applicable law.

Business transfer

In a merger, acquisition, restructuring, or sale of our business, information may transfer to the successor responsible for the Service. We will notify you of changes affecting your information and require it to remain protected under this policy unless a different use is lawfully established with the required notice and, where necessary, consent.

7. Data retention

Account data. We retain account data and study content while providing the Service to you, subject to your deletion request and the exceptions described below.

Deleted cards, decks, and folders. Deleted content has a 30-day recovery window unless you request permanent deletion sooner. Permanent deletion ends recovery; server cleanup can retain content revisions for at least 90 days from deletion and longer while they are needed by retained suggestions or shared records. Limited identifiers and deletion records may remain to prevent old devices from recreating deleted content. Your review history and study statistics can remain after card or deck deletion; account deletion follows the separate process below.

Account inactivity. We do not automatically delete free accounts or shared decks solely because they have been inactive. Account deletion and content removal are handled as described in this policy and the Terms of Service.

Account deletion. You can request deletion in the app after verifying your identity. If you own a shared deck or course, you may first need to transfer ownership or resolve that shared resource so that deleting your account does not remove another person's access without addressing ownership. You can also contact us to exercise deletion rights under applicable law.

A deletion request immediately disables account access and starts a 30-day recovery window. You may cancel within the recovery period after authenticating again. When that period ends, the deletion service processes final removal of your personal account records and content, including related authentication and subscription-management records. Removal is processed in stages, with retries for failed operations. A legal erasure request is handled under the deadlines and exceptions that apply to it.

Devices. The installation requesting deletion removes its local account data. Other installations perform cleanup when they next reconnect and receive the deletion state. We cannot instantly erase an offline device. Signing out or removing an account from one device is different from deleting the server account.

Shared contributions. Shared card and course revisions, suggestions, moderation decisions, and media needed by other authorized users may remain with the relevant shared resource. Limited records can remain to preserve shared attribution and deletion status without retaining your profile or an account that can sign in. We retain such records only for their continuing shared-content, integrity, or legal purpose.

Backups, logs, and media. Where backup copies exist, removal follows the applicable backup retention cycle rather than individual record editing. Security and operational logs are kept for investigating failures or abuse and meeting legal obligations, subject to the provider's retention controls. Database backups and media files are separate: shared media remains while an authorized resource still needs it, and unreferenced files are removed through storage cleanup.

Analytics, reporting, and email records. Analytics and reporting records are retained for measuring product use and reliability; launch-list records for sending requested messages and maintaining consent and unsubscribe preferences; and support correspondence for resolving inquiries and related disputes. Retention depends on whether those purposes remain active, applicable legal obligations, and provider retention controls. We handle applicable deletion requests across the relevant providers; deleting a Cortex account alone does not immediately remove every provider-held record.

AI records. Saved AI results follow the retention rules for the account content they become. Detailed records for settled AI operations are eligible for cleanup 90 days after settlement. Unresolved operations remain until their usage and billing can be reconciled. Limited account-linked request records remain while needed to prevent duplicate processing, manage access, or meet legal obligations; account links are removed during final account deletion where they are no longer needed. Provider-held request content has the separate retention described in Section 5; deleting a Cortex account does not instantly erase provider security logs.

Research and legal retention. Irreversibly anonymized research data and aggregate results may be retained for research because they can no longer be linked to an individual. Information subject to a valid legal retention requirement may be kept for as long as that requirement applies.

8. Children's privacy

The Service is directed to users who are at least 13 years old. We do not knowingly collect personal information from children under the age of 13.

If we learn that we have collected personal information from a child under 13, we will take steps to restrict access and delete that information as required by law. Where a higher local age or parental-consent requirement applies to particular processing, we must satisfy that requirement before carrying it out.

Cloud AI. Cloud AI features are for users aged 18 or older. Users under 18 may not use these features, even with permission from a parent or guardian.

Parents or guardians who believe their child has created an account on the Service may contact us at hello@cortexcards.app to request deletion.

9. Your rights and choices

Depending on where you live, you may have certain rights with respect to your personal data:

Correction. You may update or correct inaccurate information through your account settings or by contacting us.

Deletion. You can request account deletion through the app or by contacting hello@cortexcards.app. Section 7 explains the process, recovery period, and retained information. You can also request erasure of personal data where applicable law provides that right.

Access and data portability. To request a copy of your personal data or exercise a portability right, email hello@cortexcards.app. We may verify your identity and will provide the data and format required by applicable law.

Research opt-out. See Section 6 for how to exclude your data from future research datasets.

Marketing communications. You can unsubscribe from launch-list and other optional marketing messages using the link in the message or by contacting us. Essential sign-in, security, and account notices are separate from marketing.

To exercise these rights, contact hello@cortexcards.app. We may request proportionate identity verification and will respond within the applicable legal deadline. For GDPR/UK GDPR requests this is generally one month, with an extension only when the law permits and with notice explaining it. If a request is refused or restricted, we will explain the basis and any available complaint or appeal route.

Additional rights for EU/EEA and UK users (GDPR)

For the purposes of the GDPR and the UK GDPR, the data controller is Joshua Hoffman. We process personal data as described in this Privacy Policy.

If you are located in the European Economic Area or the United Kingdom, you have the following additional rights under the GDPR or UK GDPR (where applicable):

  • Right to object to processing based on legitimate interests
  • Right to restriction of processing in certain circumstances
  • Right to withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal
  • Right to lodge a complaint with your local data protection supervisory authority

Section 12 explains international processing and how to request information about applicable transfer safeguards.

Where the GDPR or UK GDPR applies, the following bases describe our processing. We rely on a basis only where its legal requirements are met. We may also process information to comply with legal obligations. Consent, where required, must be obtained separately and can be withdrawn; merely using Cortex is not consent to optional processing.

Data type Lawful basis
Account data (email, profile) Performance of a contract
Card content and review history Performance of a contract
Sync and device metadata Performance of a contract
Content and results for AI assistance you request or enable Performance of a contract to provide the requested feature; consent where required. Cloud AI is intended for educational material rather than sensitive personal records
AI operational usage and billing records Performance of a contract; legitimate interests in securing the Service and reconciling usage where permitted; legal obligations where applicable
Essential account communications (via Resend) Performance of a contract / legitimate interests (essential communications)
Requested launch-list messages and email engagement Consent for the requested mailing-list messages; legitimate interests in measuring email engagement where permitted, with separate consent where required
Product analytics, error reports, and account/subscription reporting (via PostHog) Legitimate interests in operating, securing, and improving Cortex, where permitted; consent where required
Preparing information for de-identified learning research Legitimate interests in understanding learning, where permitted and after assessing individual rights; consent where required. Research opt-out as described in Section 6.

10. California privacy rights

This section applies to California residents only when the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), applies to our processing of your personal information. The CCPA/CPRA applies to certain businesses based on statutory thresholds; whether it applies to us may depend on our volume of business and other factors.

Collection and use. Section 1 describes the information collected, Section 2 its purposes, Section 3 the providers receiving it, and Section 7 its retention.

Sale and sharing. We do not sell personal information for money or other valuable consideration, or share it for cross-context behavioral advertising. We use providers to perform the services described above. De-identified research is subject to Section 6 and must meet applicable de-identification requirements; calling information de-identified does not by itself remove privacy protections. If our practices change in a way that triggers sale/sharing opt-out rights, we will provide the required notice and choices, including recognition of applicable opt-out preference signals, before that change.

Your rights. Subject to verification and applicable exceptions, California residents may have the right to:

  • Know and access the categories and specific pieces of personal information we have collected
  • Delete personal information we hold, subject to legal exceptions
  • Correct inaccurate personal information
  • Opt out of the sale or sharing of personal information, where those concepts apply
  • Limit the use or disclosure of sensitive personal information in the limited circumstances where the CPRA grants that right and we process such information for those purposes
  • Non-discrimination for exercising these rights

How to submit a request. Email hello@cortexcards.app. We will respond within the timeframes required by applicable law (typically 45 days for CCPA requests, subject to extension where permitted). We may need to verify your identity before fulfilling a request.

Authorized agents. You may designate an authorized agent to submit a request on your behalf where the CCPA allows; we may require proof of authorization.

11. Data security

We take reasonable technical and organizational measures to protect your data, including:

  • Encryption of data in transit using TLS
  • Account authentication and authorization checks for access to private content
  • Software updates and technical safeguards to address security issues
  • Access controls limiting access to user data to authorized personnel who need it to operate, secure, or support the Service

No system is completely secure. In the event of a data breach that affects your personal data, we will notify you as required by applicable law.

12. International data transfers

The Service is operated from the United States. If you access the Service from outside the United States, your personal data may be transferred to the United States and to other countries where our subprocessors operate, as described in Section 3.

Transfers from the EEA, UK, or Switzerland must meet the applicable legal requirements. Where the destination does not have an adequacy decision, the transfer requires an applicable safeguard or legal exception. Standard contractual clauses and the UK transfer addendum are examples of safeguards; they must apply to the actual provider arrangement before the transfer takes place. Using Cortex does not itself supply consent for an international transfer.

Contact us for information about the processing locations and transfer arrangements applicable to your data, or to request a copy of relevant safeguards subject to necessary redactions.

13. Changes to this policy

We update the revision and effective dates when this policy changes. We will notify you of material changes and obtain consent before new processing where required by applicable law.

A policy update does not itself provide consent to new processing or retroactively authorize an incompatible use. Where the law requires consent, we will obtain it before the relevant processing begins. Your privacy rights continue to apply whether or not you continue using Cortex.

14. Contact

For questions, concerns, or requests regarding this Privacy Policy or your personal data, contact us by email at hello@cortexcards.app. We do not maintain a public mailing address.

To report copyright infringement, follow the copyright reporting instructions in Section 8 of our Terms of Service.

Cortex

Flashcards for Mac,
iPhone, and iPad.

Product

How it worksMoving from AnkiPricing

Resources

Questions & answersLaunch notificationContact

Appearance

© 2026 Cortex
PrivacyTerms